Open source · Apache-2.0
smb-sandbox: a realistic fake small business for testing AI agents
smb-sandbox is TeamShift's open-source sandbox of a realistic, fully fictional small business: a deterministic data generator plus mock CRM, inbox, calendar, invoicing and phone MCP servers, so you can test AI agents without touching real customer accounts.
Who it is for
Developers and teams building AI agents or automations that will touch business systems: a CRM, a shared inbox, a calendar, an invoicing tool, a phone log. If you need to see what your agent actually does to a business before it ever gets real credentials, or you want a repeatable test you can rerun after every prompt or model change, this is the setup it was built for.
What is inside
- fake-business (
@teamshift/fake-business) generates one coherent fictional business: customers, contacts, leads, deals, quotes, jobs, invoices, payments, email and SMS threads, calls, tasks and an event timeline. Records reference each other, timestamps are causally ordered, and realistic mess (an unanswered lead, an invoice attached to the wrong job, a duplicate contact) is injected on purpose and labeled in ananomalieslist. It has zero runtime dependencies. - sandbox-mcp (
@teamshift/sandbox-mcp) serves that business as mock Model Context Protocol servers grouped into toolsets:crm,inbox,calendar,invoicing,phoneandadmin. Changes are validated the way a real system would validate them, recorded in an audit log, and never leave the process. Sending an email or SMS only writes to an outbox. - smb-workflows (
@teamshift/smb-workflows) is the third part, still in development: a cookbook of small-business tasks such as quote follow-up, missed-call callbacks, invoice reminders and CRM cleanup, each with a verifier that grades the end state of the sandbox rather than what the agent says it did.
How it works
The generator is seeded. The same industry, seed, size, as-of date, history length and messiness always produce byte-identical output, on any machine, because it ships its own PRNG and word lists and never calls the network. Three industries ship today: home-services (an HVAC and plumbing contractor), dental-clinic and marketing-agency.
Every injected problem is labeled with the records involved, a one-sentence description, and the money at risk. That list is your answer key. sandbox-mcp hides it from the agent by default (it appears as the sandbox://anomalies resource only with --expose-answers), so you can score precision and recall honestly.
When the run ends, --state-out run.json writes the final state of every record, an audit log of every attempted change (including errors), and the outbox. Grade that end state, not the transcript.
Quickstart
# A fictional dental clinic, summarized
npx @teamshift/fake-business --industry dental-clinic --seed 7 --summary
# The full dataset as JSON
npx @teamshift/fake-business --industry home-services --seed 42 > business.json
# Give Claude Code a sandboxed business to operate
claude mcp add sandbox -- npx -y @teamshift/sandbox-mcpsandbox-mcp also works with Claude Desktop, Cursor, VS Code and any other MCP client, over stdio or Streamable HTTP (--http 8787).
Example
--industry home-services --seed 42 --size small always produces Copper Kettle Plumbing & Air in the fictional town of Birchford, MN: 15 customers, 14 leads, 12 deals, 13 invoices, 87 messages, 34 calls, 303 timeline events, 6 upcoming appointments and 11 labeled anomalies. One of them reads:
Estimate Q-1217 for Aryana Hall ($2,170.00) was sent 2026-05-08 and never followed up; it expired 2026-06-07 with no decision recorded.An agent asked to "follow up on every stale quote" should find that record. The anomaly list tells you whether it did, and the audit log tells you what else it touched.
Limitations
- The schema is fixed: one small-business model covering CRM, quotes, jobs, billing and communications. For arbitrary tables of plausible values, a general-purpose faker is the better fit.
- Three industries ship today. Adding one is a single file in the repo.
- The HubSpot and QuickBooks exports are shaped for each product's import wizard, but they are not official templates. Review the column mapping and import into a sandbox account first.
- sandbox-mcp enforces common business rules (pipeline stages, no overpayments, no double-booked technicians), not every rule your real systems have.
- The smb-workflows cookbook is not published yet.
FAQ
What is smb-sandbox?
smb-sandbox is an open-source, Apache-2.0 project from TeamShift that gives AI agents a realistic fictional small business to work in. It combines a deterministic data generator (fake-business) with mock CRM, inbox, calendar, invoicing and phone MCP servers (sandbox-mcp).
Does sandbox-mcp send real emails or texts?
No. Nothing leaves the process. Sending an email or SMS appends the message to its thread and to an outbox, and every address uses the reserved .example domain or the fictional 555-0100 to 555-0199 phone range.
How do I score an agent with smb-sandbox?
Run the agent against sandbox-mcp with --state-out, then compare the final dataset with the labeled anomalies from the original dataset and use the audit log to penalize errors, destructive actions or policy violations. Leave out the admin toolset so the agent cannot reset its own run.
Is the data safe to publish?
Yes. Every dataset is marked synthetic, emails use the .example domain, phone numbers sit in the range set aside for fiction, and company, town and street names are invented. Dental records contain no real health information.
Which MCP clients work with sandbox-mcp?
Any Model Context Protocol client. The README has setup snippets for Claude Code, Claude Desktop, Cursor and VS Code. It runs over stdio by default, or Streamable HTTP with --http.